Junglewise Threat Intelligence

CVE-2026-47994: Adobe Commerce stored XSS in form fields

CVE-2026-47994 · Severity: high · CVSS 8.7 · Published 2026-07-14

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce, Adobe Commerce B2b, Adobe Magento Open Source, Adobe Commerce Webhooks Plugin. Vendors: Adobe.

Executive brief

Adobe Commerce, a popular e-commerce platform, is affected by a security flaw that allows attackers to inject malicious scripts into the website. An attacker with low-level account access can use this to target other users, including administrators, potentially stealing their login sessions or taking control of their accounts. This could lead to unauthorized access to customer data or the store's management interface.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Commerce, Magento Open Source, and related components. The flaw is caused by improper neutralization of input during web page generation, specifically within certain form fields. A remote attacker with low-privileged credentials can inject malicious JavaScript that is subsequently stored on the server. When a victim (such as an administrator) views the affected page, the script executes in their browser context. This can lead to session hijacking or unauthorized actions performed on behalf of the victim. The vulnerability has been addressed in the July 2026 security updates.

Affected products

  • Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
  • Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
  • Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
  • Adobe Adobe Commerce Webhooks Plugin <= 1.20.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats